CVE-2014-8425 describes an authentication bypass vulnerability in the ARRIS VAP2500 management portal, specifically in firmware versions prior to FW08.41. This critical vulnerability allows remote, unauthenticated attackers to read configuration files and obtain sensitive credentials. With a CVSS score of 7.8 and a FAUCET Risk Score of 94/100, it poses a significant risk due to its low attack complexity and high impact on confidentiality. While not actively exploited in the wild or on the KEV catalog, an exploit (EDB-35372) is publicly available on ExploitDB, though it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 08.41CPE matchmatch criteria | cpe:2.3:o:arris:vap2500_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.